Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2261+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
NEWS

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

PortSwigger researcher Gareth Heyes demonstrated at Black Hat USA 2026 that CSS and HTML within emails can escape message boundaries to capture typed passwords, steal session tokens, and leak IP addresses across Outlook, Gmail, Yahoo, Proton Mail, Fastmail, and AOL Mail.

Dylan H.

News Desk

August 8, 2026
5 min read

CSS Escapes Email Sandbox to Capture Credentials in Six Major Webmail Platforms

Security researcher Gareth Heyes of PortSwigger Web Security presented groundbreaking research at Black Hat USA 2026 revealing that CSS and HTML within email content can escape message rendering boundaries and interact with webmail interface controls — allowing attackers to capture passwords typed by recipients, steal session tokens, and leak IP addresses without the recipient suspecting anything is wrong.

The research affects six major webmail platforms: Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. Some vulnerabilities remained unpatched at the time of public disclosure on August 6, 2026.


The Attack Techniques

1. Password Capture via Label-Jacking (Outlook + Firefox)

The most alarming attack uses an HTML label element within the email to masquerade as a password field in the webmail interface itself. When a recipient views the malicious email in Outlook on Firefox, the label element hijacks the focus and captures keystrokes — including passwords — in real time as the user types them.

Attack Chain:
Malicious email → label element in body → binds to Outlook password field
→ User types password → keystrokes captured → exfiltrated to attacker

This technique exploits a fundamental design assumption: that HTML within an email cannot bind to elements outside the email body. The label-jacking attack violates that assumption without any JavaScript — using only HTML and CSS.

Status: Remained active at time of publication (August 6, 2026).

2. Token Exfiltration via Paste-Timing Attack (Yahoo Mail + AOL)

Yahoo Mail and AOL Mail are vulnerable to a paste-timing attack that exploits how Firefox processes pasted HTML content before sanitization runs. By carefully timing when CSS rules are evaluated relative to paste events, an attacker's crafted email can reconstruct enough information to extract authentication tokens from the webmail session.

This is a subtle race-condition-class vulnerability — it requires no user error beyond reading a malicious email.

3. Image-Set Exfiltration + Prompt Injection (Gmail)

Gmail's sanitization blocks most direct data exfiltration, but the image-set() CSS function can be used to make outbound requests even after sanitization. When combined with connected services (demonstrated using prompt injection against AI assistant integrations), the attack can:

  1. Trigger token confirmation emails from connected services
  2. Intercept and extract credentials through the connected account's reply path

This demonstrates a new class of attack: CSS-initiated prompt injection in AI-enhanced webmail environments.

4. IP Address Leak via Tracker Protection Bypass (Proton Mail)

Proton Mail's tracker protection — designed to prevent image beacons from revealing recipients' IP addresses — can be bypassed. The bypass allows an attacker to:

  • Determine the precise IP address of the email recipient
  • Identify the exact time the email was opened
  • Correlate multiple email opens to build a timing fingerprint

Status: Proton's proxy bypass no longer functioned at time of publication; Proton appears to have silently patched it.


Affected Platforms and Status

PlatformVulnerabilityStatus at Publication
OutlookLabel-jacking password captureUNPATCHED
Gmailimage-set() bypass + prompt injectionUNPATCHED
Yahoo MailPaste-timing token exfiltrationUnder investigation
AOL MailPaste-timing token exfiltrationUnder investigation
FastmailTwo CSS mutation bugsPATCHED
Proton MailTracker protection bypassPATCHED

Why This Is Significant

Email HTML sanitization has long been treated as a solved problem — webmail providers invest heavily in stripping dangerous content before rendering. This research demonstrates that even well-implemented sanitization can fail when:

  1. CSS interacts with the surrounding DOM beyond the email boundary
  2. Timing side-channels expose data during sanitization processing
  3. Feature interactions between CSS, browser behavior, and connected services create unexpected attack surfaces
  4. AI integrations introduce new prompt injection vectors reachable via CSS-initiated requests

The attacks require no JavaScript, operate within standard HTML and CSS feature sets, and exploit browser and webmail interactions that no sanitization engine was designed to anticipate.


Mitigations

For End Users

  1. Use a dedicated browser for webmail rather than your primary browser — reduces cross-domain data exposure
  2. Do not type passwords while an email is open in the same browser tab
  3. Use hardware security keys (FIDO2/WebAuthn) — immune to password capture attacks
  4. Use email clients (Thunderbird, Apple Mail) rather than webmail where possible — desktop clients do not share a DOM with the rest of the interface
  5. Consider plaintext email for high-security communications

For Webmail Providers

Heyes recommends the following mitigations:

MitigationBenefit
Sandboxed iframes for email renderingComplete DOM isolation — no label binding across boundary
Strict CSS restrictionsBlock image-set() and dangerous selectors
Block select menus in email HTMLRemoves UI hijacking vectors
Custom attribute validationPrevent binding to interface elements
Content Security Policy for email framesRestrict outbound request paths

Responsible Disclosure

Gareth Heyes reported these vulnerabilities to affected vendors prior to the Black Hat USA 2026 presentation. Fastmail and Proton Mail issued fixes before the public disclosure. Google, Microsoft, Yahoo, and AOL received reports and were given time to remediate — some issues remained open at publication.

The full research will be detailed in a PortSwigger blog post. Conference slides from the Black Hat presentation contain technical demonstrations of each attack chain.


References

  • The Hacker News — New CSS Attacks Can Break Webmail Defenses
  • PortSwigger Research — Gareth Heyes
  • Black Hat USA 2026 — Briefings Schedule

Related Reading

  • Head Mare Hacktivists Breach TrueConf to Trojanize Installers
  • CVE-2026-19264: Critical Path Traversal in Postiz
#CSS Injection#Webmail#Email Security#Black Hat#PortSwigger#Web Security#Credential Theft#Session Hijacking

Related Articles

AI-Assisted HTTP Terminator Finds Novel Desync Techniques and Apache Zero-Day

PortSwigger researcher James Kettle unveiled HTTP Terminator at Black Hat USA 2026 — an autonomous AI system that invented three new HTTP request smuggling techniques and discovered an Apache Traffic Server zero-day by testing 30,000 attack vectors across 30,000 websites.

6 min read

Data Breach Exposes Up to 14.2 Million Email Logins at Six ISPs

Japanese telecom giant KDDI Corporation disclosed a data breach affecting up to 14.22 million email accounts across six ISPs — including Nifty, Biglobe,...

5 min read

Suspicious Polyfill Login Prompts Pop Up on Toshiba, Muji Websites

Tech giant Toshiba and mega-retailer Muji have warned visitors that suspicious sign-in screens appearing on their websites could be harvesting credentials — a…

5 min read
Back to all News